Cookies
Last updated 19 September 2026.
This page lists everything this site keeps in your browser. It is short because there is very little: two cookies for signing in, and one for counting visitors. Nothing here is used to advertise to you, and nothing here is sold or shared for anyone else's purposes.
What your browser keeps
| Name | What it is for | How long it lasts | Strictly necessary |
|---|---|---|---|
| sb-<project>-auth-token | Keeps you signed in, so the app knows the radar and settings you open are yours. It holds your sign-in session, not your companies or settings. A long session can be split across sb-<project>-auth-token.0, .1 and so on. Those are the same cookie in pieces. | Set when you follow a sign-in link. Renewed while you use the app, and lasts up to 400 days after your last visit, the longest a browser allows. Removed if the session ends. | Yes |
| sb-<project>-auth-token-code-verifier | A one-time secret created when you ask for a sign-in link. When you click the link it proves the request came from this browser, so a link that leaks out of your inbox cannot sign in somebody else. | Deleted as soon as you use the link. If you never use it, the browser drops it after 400 days. | Yes |
| ph_<project>_posthog | Counts you once rather than twice. It holds a random id for this browser and the current visit, so we can tell how many people came to the site, which pages they read, and how many went on to sign up. It is not your name or your email, and it is not used to show you advertising anywhere. | Set on your first visit. Lasts one year, renewed while you keep visiting. | No |
| ph_opt_in_out_<project> | Remembers that you said no, so you are not counted and are not asked again in this browser. It exists only if you opt out. | One year. | No |
| ph_<project>_window_id | Session storage, not a cookie: it ties the pages you open in one tab into a single visit. Alongside it, ph_<project>_primary_window_exists does the same job across two tabs. | Until you close the tab. | No |
<project> stands for an identifier of the service involved — the Supabase project that runs sign-in, or the PostHog project that counts visits. Every one of these is sent only to this site. The analytics code is PostHog's, but your browser loads it from roles.watch and sends its measurements to roles.watch, and we pass those on to PostHog — so no other domain is contacted from this page and none of them can set a cookie of their own.
What we do not use
No advertising, no ad networks, no tracking pixels, no embedded videos or social buttons, and nothing that follows you to other websites. We do not sell or share what we measure, and we do not use it to build a profile of you for anybody else.
What the analytics actually record
Which pages are opened and in what order, roughly where in the world the visit came from, the kind of browser, the site that linked you here, and a handful of named steps: a company looked up, a sign-in link asked for, an account created, a company added, a first email sent. We record those to answer questions like “did anyone use this” and “where do people give up”. Once you have an account, your email address is attached to them, so that we can get in touch about what we see, and the name of a company is recorded when you add one, so that we can see which employers people most want watched. Your list as a whole is never sent, and none of this is used to advertise to you. The privacy page says more.
We also record playback of some visits, so we can see where a page confused somebody. Text is masked before it leaves your browser: the playback shows the shape of the page and where you clicked, not the words on it, not what you typed, and not which companies you follow.
How to say no
If your browser sends Do Not Track or Global Privacy Control, nothing is recorded at all — no cookie is set and no measurement is sent. Both are a setting in your browser or an extension, and they work on this site today without you asking us.
Blocking or clearing this site's cookies also works, and so does any content blocker set to block PostHog. None of it affects the product: the analytics cookie has no part in signing in or in anything the app does for you.
Removing them
Clearing this site's cookies in your browser signs you out and resets the analytics id. Nothing else is lost: your companies and settings live in your account, not in the browser. Signing out removes the analytics cookie too, so a shared computer does not carry your visit into the next person's.